# Protect sensitive PHP files
<Files "config.php">
    Order deny,allow
    Deny from all
</Files>

# Secure directories
Options -Indexes

# Set default index file
DirectoryIndex index.html

# Security headers
<IfModule mod_headers.c>
    # Prevent clickjacking
    Header set X-Frame-Options "SAMEORIGIN"
    # XSS protection
    Header set X-XSS-Protection "1; mode=block"
    # Prevent MIME-sniffing
    Header set X-Content-Type-Options "nosniff"
    # Referrer policy
    Header set Referrer-Policy "strict-origin-when-cross-origin"
</IfModule>

# PHP security
<IfModule mod_php.c>
    # Disable showing PHP errors to visitors
    php_flag display_errors off
    # Disable remote file inclusions
    php_flag allow_url_fopen off
    php_flag allow_url_include off
</IfModule>

# Control access to API endpoints
<FilesMatch "^api\.php$">
    # Allow specific HTTP methods
    <LimitExcept GET POST OPTIONS>
        Deny from all
    </LimitExcept>
</FilesMatch> 